Privacy
Privacy Notice
1. Who we are
BirdSaid is operated by Praeco Innovation Ltd, a company registered in Cyprus under registration number HE 469106, with its registered office at Loizou Askani 8, 3110 Limassol, Cyprus (“Praeco”, “BirdSaid”, “we”).
2. Our role
BirdSaid is strictly a consumer product. Praeco acts as controller for the personal data it processes to provide and secure the service, including customer-selected recordings, transcripts, speaker labels and voice memory. The user still decides what to record and submit and is responsible for participant notices, permissions and applicable recording rules. A user's personal or household context does not remove Praeco's own data-protection obligations.
3. Data we process
- account identity, verified-email binding, declared country and region, login and security events;
- audio/video files, meeting audio, titles, timing and provider metadata;
- transcripts, diarised speaker clusters, names and user corrections;
- voice templates, a short audio snippet supporting each print, match scores and enrolment records;
- payment customer IDs, purchases, credit balances, refunds and invoices (card details are handled by Stripe);
- device, browser, IP, request and error information needed to operate and secure the service, including Cloudflare's coarse request country as a mismatch signal; and
- support communications.
4. Why and on what basis
We process data to provide the requested service and administer the contract; protect BirdSaid and customers; comply with tax, accounting and legal duties; and improve reliability using appropriately minimised operational data. Where voice templates are biometric or special-category data, BirdSaid requires a separate enrolment attestation and restricts locations where its current flow does not meet a known requirement. Depending on context, processing may rely on explicit consent or another condition available to the relevant controller. Customers must identify and document their own lawful basis.
5. Voice memory
A customer's voice library is account-isolated, encrypted at rest, limited in size, and used only to suggest or apply names in that customer's recordings. The first print for a person requires an explicit action. Supporting snippets can be played and deleted. Voice-memory availability uses the country/region the customer confirms. Cloudflare's coarse request country and Stripe billing country may flag a mismatch, but neither silently replaces that declaration or decides availability. See the Voiceprint Notice.
6. Sharing and subprocessors
We disclose data only as needed to operate BirdSaid, follow a customer's instructions, complete payments, protect rights and safety, or comply with law. Current infrastructure and processing providers are listed on our Subprocessor List. We do not sell personal data or use customer audio, transcripts, or voiceprints for advertising.
7. Chrome extension and Limited Use
The optional BirdSaid Meeting Recorder observes whether the user-selected tab is a supported meeting provider. It does not store or transmit the full meeting URL, join token, page content, chat, participant list or browsing history. After the user deliberately starts recording, tab audio and optional microphone audio remain in extension memory until the user chooses Upload or Discard. Upload sends the audio, an expiring account-scoped recorder credential, provider, generic title, timing, timezone, duration and stop reason over HTTPS to BirdSaid. A failed upload remains only in the current extension runtime for an explicit retry.
BirdSaid's use of information received from Chrome APIs complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. We use it only to provide and secure the customer-visible meeting recording and transcription feature. The extension transfers it only to BirdSaid; Cloudflare and Mistral process it for BirdSaid as described on the Subprocessor List. It is not sold, used for personalised advertising, credit or other eligibility decisions, or any unrelated purpose. Humans do not listen to or read extension-derived customer content except with the customer's specific permission for support, where necessary for security, where legally required, or after the data has been aggregated and anonymised for internal operations. The extension does not load or execute remote executable code.
8. International transfers
Providers may process data outside the country where a person lives. Where EU/EEA transfer restrictions apply, we use an adequacy decision or appropriate safeguards such as approved standard contractual clauses, together with supplementary measures where appropriate.
9. Retention and deletion
BirdSaid keeps information only for the service, security, legal, and accounting purposes described here. Current demo defaults delete raw meeting audio 30 days after upload, standard transcripts 180 days after creation, short-lived dictations after 7 days, customer security events after 90 days, stale recorder credential history after 30 days, and voice profiles after 365 days without qualifying activity. If a confirmed location becomes restricted, enrolment and matching stop immediately; existing profiles remain available for review, account export and deletion for 30 days, then are automatically deleted. A missing or malformed policy fails closed for use but does not itself start deletion. Users can delete individual transcripts, archived meeting audio, voice samples, whole voice profiles, or their account. Account deletion immediately removes active customer content, voiceprint snippets, enrolment receipts, and recorder credentials, and pseudonymises the retained credit ledger. BirdSaid does not make a separate backup copy of R2/KV recordings, transcripts or voiceprints. Cloudflare-managed D1 Time Travel can retain database history for up to 30 days; an independent secret-hashed deletion tombstone remains for 31 days to prevent a restored login and reapply account pseudonymisation after a recovery. Minimal transaction, invoice, tax, refund and dispute evidence is retained for 10 years from the end of the transaction year for Cyprus/EU accounting and intended OSS obligations; BirdSaid does not retain card details.
10. Your choices and rights
Depending on applicable law, people may request access, correction, deletion, restriction, portability, or objection, and may withdraw consent without affecting earlier lawful processing. Users can download a JSON account export and delete voice memory or the whole account from Account settings. Audio is not embedded in the JSON export; authenticated playback remains available until the underlying content is deleted. EU/EEA residents may complain to a supervisory authority, including the Cyprus Commissioner for Personal Data Protection.
11. Recording other people
The customer decides what to record and whose names or voiceprints to store. Customers must notify participants and obtain consent or other permission where required. BirdSaid is not designed for covert recording, surveillance, or identifying an unknown person.
12. Children
BirdSaid is not intended for children or for recordings primarily involving children. Do not create voiceprints for minors.
13. Security and changes
We use access controls, tenant isolation, encryption, logging, deletion controls, and provider review proportionate to the data. No system is completely secure. Material changes will be dated here and, where appropriate, notified in the service.
14. Contact
See our Contact page. A public privacy email and telephone number are launch requirements and will be added before BirdSaid accepts public customers.